Iran-Linked Hackers Wield Sophisticated Modular Framework in Targeted Cyberattacks
A highly advanced Iranian hacking group has been using a cutting-edge, modular command-and-control (C&C) framework to infiltrate and compromise organizations in Israel. Dubbed Cavern Manticore by cybersecurity researchers at Check Point, this sophisticated threat actor focuses its attacks on government entities and IT providers, raising concerns about the potential for data theft and disruption.
At the heart of Cavern Manticore’s operations is a modular C&C framework built using .NET, allowing the attackers to tailor their approach to each target. The framework’s adaptable toolset includes various compilation formats used across its components, serving as an anti-analysis layer that makes it difficult for security researchers to reverse-engineer and understand the code. This innovative technique effectively thwarts traditional forms of code obfuscation, making it a challenging task for analysts to dissect and analyze the framework.
The infection chain begins with the exploitation of a software vulnerability, using SysAid’s update feature to sideload malicious code. Once inside, the Cavern agent establishes command-and-control communication with its operators, who can then instruct the agent to fetch additional modules tailored to the target environment. These modules support various malicious activities, including file operations, database manipulation, and network reconnaissance.
The framework’s modular design allows for a high degree of flexibility and customization, enabling the attackers to extend their access to compromised environments and evade detection. To further complicate matters, Cavern Manticore isolates each module into its dedicated AppDomain, terminating it after use to eliminate any analyzable artifacts. The agent also deletes all files in the working directory except for those necessary for communication, log files, and configuration.
While some speculate that the framework was built using artificial intelligence (AI) models, the presence of code comments, typos, and inconsistencies suggests human involvement in its development. This nuanced approach underscores the evolving nature of cyber threats, where attackers are increasingly leveraging sophisticated tools to stay ahead of their adversaries.
In observed campaigns targeting Israeli organizations, Cavern Manticore has demonstrated a deep understanding of IT supplier chains within Israel’s cyber ecosystem. By moving from compromised IT providers to second-hop targets before reaching intended organizations, the threat actor has showcased its ability to navigate complex networks and evade detection.
As security professionals and organizations, it is essential that we stay vigilant in the face of these evolving threats. Cavern Manticore’s modular framework serves as a reminder of the need for continuous monitoring, robust incident response planning, and the importance of staying informed about emerging threat tactics. By understanding the complexities of these attacks and adapting our defenses accordingly, we can better protect ourselves against the sophisticated cyber threats that are increasingly becoming a reality.
Source: SecurityWeek — 2026-07-07